Yep!

ifconfig eth1 up

Don't bother assigning it an IP.  Then start snort with the -i eth1 option.
(or whatever interface you want to listen on.  FYI, you should always use
the -u option also to run as a non-priveledged user, running snort as root
could have bad consequences if some sort of buffer overflow exploit is
discovered.

Jay

> -----Original Message-----
> From: Bob Tanner [mailto:tanner at real-time.com]
> Sent: Friday, January 19, 2001 1:04 AM
> To: tclug-list at mn-linux.org
> Subject: [TCLUG] Snort on interface without IP?
> 
> 
> I read an article about using iptraf on an interface without 
> an IP address, just
> in promiscious mode.
> 
> Anyone know if Snort will work this way.
> 
> http://www.zdnet.com/enterprise/stories/main/0,10228,2675100,00.html
> 
> -- 
> Bob Tanner <tanner at real-time.com>       | Phone : (952)943-8700
> http://www.mn-linux.org                 | Fax   : (952)943-8500
> Key fingerprint =  6C E9 51 4F D5 3E 4C 66 62 A9 10 E5 35 85 39 D9 
> 
> _______________________________________________
> tclug-list mailing list
> tclug-list at mn-linux.org
> https://mailman.mn-linux.org/mailman/listinfo/tclug-list
>